Patentable/Patents/US-20260230826-A1
US-20260230826-A1

Methods and Systems to Detect Rogue Hotspots

PublishedAugust 6, 2026
Assigneenot available in USPTO data we have
Technical Abstract

Methods, systems, and apparatuses are described for identifying unauthorized (e.g., rogue) access points. Authorized access points can detect the presence of rogue access points by determining signal strengths associated with other access points. A detected variance from an expected signal strength can indicate a presence of a rogue access point.

Patent Claims

Legal claims defining the scope of protection, as filed with the USPTO.

1

receiving, from a plurality of authorized network devices, signal strength measurements associated with network identifier information; determining, based on relative differences among the signal strength measurements from the plurality of authorized network devices, that the network identifier information is associated with an unauthorized network device; and based on a determination that the network identifier information is associated with the rogue network device, sending a remediation message. . A method comprising:

2

claim 1 . The method of, wherein the signal strength measurements comprise received signal strength indicator (RSSI) measurements, and wherein determining that the network identifier information is associated with the unauthorized network device comprises determining that a variance among the RSSI measurements received from the plurality of authorized network devices that is inconsistent with a baseline signal strength associated with the network identifier information.

3

claim 2 . The method of, wherein the baseline signal strength is determined by summating or averaging signal strength measurements associated with the network identifier information received from the plurality of authorized network devices during an initial probe or scan of a network.

4

claim 1 . The method of, wherein the network identifier information comprises one or more of a service set identifier (SSID) and a media access control (MAC) address associated with an authorized network device of the plurality of authorized network devices.

5

claim 1 . The method of, wherein the remediation message causes a compromised network device associated with the network identifier information to deauthenticate or disassociate one or more user devices in communication with the compromised network device based on the network identifier information.

6

claim 5 . The method of, wherein the remediation message further causes the compromised network device to change the network identifier information to new network identifier information, and wherein the one or more user devices reconnect to the compromised network device based on the new network identifier information.

7

claim 1 . The method of, further comprising generating or updating a master list comprising the network identifier information and signal strength information associated with the plurality of authorized network devices, wherein the master list is updated based on a periodic probe or scan of a network performed by the plurality of authorized network devices.

8

one or more processors; and receive, from a plurality of authorized network devices, signal strength measurements associated with network identifier information; determine, based on relative differences among the signal strength measurements from the plurality of authorized network devices, that the network identifier information is associated with an unauthorized network device; and a memory storing processor-executable instructions that, when executed by the one or more processors, cause the apparatus to: based on a determination that the network identifier information is associated with the rogue network device, send a remediation message. . An apparatus comprising:

9

claim 8 . The apparatus of, wherein the signal strength measurements comprise received signal strength indicator (RSSI) measurements, and wherein the processor-executable instructions, when executed by the one or more processors, that the apparatus to determine that the network identifier information is associated with the unauthorized network device comprises processor-executable instructions, when executed by the one or more processors, that cause the apparatus to determine that a variance among the RSSI measurements received from the plurality of authorized network devices that is inconsistent with a baseline signal strength associated with the network identifier information.

10

claim 9 . The apparatus of, wherein the baseline signal strength is determined by summating or averaging signal strength measurements associated with the network identifier information received from the plurality of authorized network devices during an initial probe or scan of a network.

11

claim 8 . The apparatus of, wherein the network identifier information comprises one or more of a service set identifier (SSID) and a media access control (MAC) address associated with an authorized network device of the plurality of authorized network devices.

12

claim 8 . The apparatus of, wherein the remediation message causes a compromised network device associated with the network identifier information to deauthenticate or disassociate one or more user devices in communication with the compromised network device based on the network identifier information.

13

claim 12 . The apparatus of, wherein the remediation message further causes the compromised network device to change the network identifier information to new network identifier information, and wherein the one or more user devices reconnect to the compromised network device based on the new network identifier information.

14

claim 8 . The apparatus of, wherein the processor-executable instructions, when executed by the one or more processors, further the apparatus to generate or updating a master list comprising the network identifier information and signal strength information associated with the plurality of authorized network devices, wherein the master list is updated based on a periodic probe or scan of a network performed by the plurality of authorized network devices.

15

receive, from a plurality of authorized network devices, signal strength measurements associated with network identifier information; determine, based on relative differences among the signal strength measurements from the plurality of authorized network devices, that the network identifier information is associated with an unauthorized network device; and based on a determination that the network identifier information is associated with the rogue network device, send a remediation message; and a computing device configured to: an authorized network device of the plurality of authorized network devices configured to receive the remediation message. . A system comprising:

16

claim 15 . The system of, wherein the signal strength measurements comprise received signal strength indicator (RSSI) measurements, and wherein the computing device configured to determine that the network identifier information is associated with the unauthorized network device comprises the computing device configured to determine that a variance among the RSSI measurements received from the plurality of authorized network devices that is inconsistent with a baseline signal strength associated with the network identifier information.

17

claim 16 . The system of, wherein the baseline signal strength is determined by summating or averaging signal strength measurements associated with the network identifier information received from the plurality of authorized network devices during an initial probe or scan of a network.

18

claim 15 . The system of, wherein the network identifier information comprises one or more of a service set identifier (SSID) and a media access control (MAC) address associated with an authorized network device of the plurality of authorized network devices.

19

claim 15 . The system of, wherein the remediation message causes a compromised network device associated with the network identifier information to deauthenticate or disassociate one or more user devices in communication with the compromised network device based on the network identifier information.

20

claim 19 . The system of, wherein the remediation message further causes the compromised network device to change the network identifier information to new network identifier information, and wherein the one or more user devices reconnect to the compromised network device based on the new network identifier information.

21

claim 15 . The system of, wherein the computing device is further configured to generate or updating a master list comprising the network identifier information and signal strength information associated with the plurality of authorized network devices, wherein the master list is updated based on a periodic probe or scan of a network performed by the plurality of authorized network devices.

Detailed Description

Complete technical specification and implementation details from the patent document.

This application is a continuation of U.S. patent application Ser. No. 17/129,707, filed Dec. 21, 2020, which is a continuation of U.S. patent application Ser. No. 15/809,825, filed Nov. 10, 2017, issued as U.S. Pat. No. 10,911,956 on Feb. 2, 2021, the entireties of which are hereby incorporated by reference.

Rogue hotspots (e.g., unauthorized access points) masquerade as authorized access points to trick a user and/or user device into connecting to the rogue hotspot by broadcasting network credentials that resemble an authorized access point. A device (e.g., user device, mobile device, network device, etc.) can connect to the rogue access point unaware that it is not connected to an authorized access point. The rogue access point can then obtain sensitive information associated with the device and/or harm the device. Rogue hotspots have presented a challenge and, as yet, no workable solution has been developed for their detection. These and other shortcomings are addressed by the methods and systems disclosed herein.

It is to be understood that both the following general description and the following detailed description provide examples, are explanatory only, and are not restrictive. Provided are methods and systems for detecting rogue hotspots (e.g., unauthorized access points).

“Man-in-the-middle” attacks can involve rogue hotspots. Rogue hotspots are devices that copy identifier information such as service set identifiers (SSIDs) and media access control (MAC) addresses associated with access points to trick devices in to believing they are in communication with the access point when they are actually in communication with the rogue hotspot. When a device, such as a user device, smartphone, laptop, etc., connects to the rogue hotspot, the rogue hotspot can obtain access to data communications associated with the device because the device is now transmitting and receiving data via the rogue access point.

One or more access points can be used to detect the rogue hotspot by determining, via periodic scans of the network, the presence of other access points and creating/storing a list of the access points. The list of the access points can also comprise signal strength information associated with each of the one or more access points. Subsequent scans of the network can be used to look for the characteristics of a rogue hotspot, such as inconsistent or fluctuating signal strength measurements which can indicate that a rogue hotspot has copied the identifier information of an access point (e.g., a now compromised access point). The copied identifier information can be stored as compromised identifier information. Based on the detection of the rogue hotspot, actions can be taken to remove the rogue hotspot from the network, such as causing the compromised access point to disassociate (e.g., disconnect, cease communication, deauthenticate, etc.) with devices (e.g., user devices) in communication with the compromised access point and generating new identifier information for the compromised access point, for example.

Additional advantages will be set forth in part in the description which follows or may be learned by practice. The advantages will be realized and attained by means of the elements and combinations particularly pointed out in the appended claims.

Before the present methods and systems are disclosed and described, it is to be understood that the methods and systems are not limited to specific methods, specific components, or to particular implementations. It is also to be understood that the terminology used herein is for the purpose of describing particular examples only and is not intended to be limiting.

As used in the specification and the appended claims, the singular forms “a,” “an,” and “the” include plural referents unless the context clearly dictates otherwise. Ranges may be expressed herein as from “about” one particular value, and/or to “about” another particular value. When such a range is expressed, another example includes from the one particular value and/or to the other particular value. Similarly, when values are expressed as approximations, by use of the antecedent “about,” it will be understood that the particular value forms another example. It will be further understood that the endpoints of each of the ranges are significant both in relation to the other endpoint, and independently of the other endpoint.

“Optional” or “optionally” means that the subsequently described event or circumstance may or may not occur, and that the description includes examples where said event or circumstance occurs and examples where it does not.

Throughout the description and claims of this specification, the word “comprise” and variations of the word, such as “comprising” and “comprises,” means “including but not limited to,” and is not intended to exclude, for example, other components, integers or steps. “Such as” is not used in a restrictive sense, but for explanatory purposes.

Disclosed are components that can be used to perform the disclosed methods and systems. These and other components are disclosed herein, and it is understood that when combinations, subsets, interactions, groups, etc. of these components are disclosed that while specific reference of each various individual and collective combinations and permutation of these may not be explicitly disclosed, each is specifically contemplated and described herein, for all methods and systems. This applies to all examples of this application including, but not limited to, steps in disclosed methods. If there are a variety of additional steps that can be performed it is understood that each of these additional steps can be performed with any specific example or combination of examples of the disclosed methods.

The present methods and systems may be understood more readily by reference to the following detailed description of preferred examples and other examples included therein and to the Figures and their previous and following description.

As will be appreciated by one skilled in the art, the methods and systems may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware components. Furthermore, the methods and systems may take the form of a computer program product on a computer-readable storage medium having computer-readable program instructions (e.g., computer software) embodied in the storage medium. More particularly, the present methods and systems may take the form of web-implemented computer software. Any suitable computer-readable storage medium may be utilized including hard disks, CD-ROMs, optical storage devices, or magnetic storage devices.

Examples of the methods and systems are described below with reference to block diagrams and flowcharts of methods, systems, apparatuses and computer program products. It will be understood that each block of the block diagrams and flowcharts, and combinations of blocks in the block diagrams and flowcharts, respectively, can be implemented by computer program instructions. These computer program instructions may be loaded onto a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions which execute on the computer or other programmable data processing apparatus create a means for implementing the functions specified in the flowchart block or blocks.

These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including computer-readable instructions for implementing the function specified in the flowchart block or blocks. The computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions that execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks.

Accordingly, blocks of the block diagrams and flowcharts support combinations of means for performing the specified functions, combinations of steps for performing the specified functions and program instruction means for performing the specified functions. It will also be understood that each block of the block diagrams and flowcharts, and combinations of blocks in the block diagrams and flowcharts, can be implemented by special purpose hardware-based computer systems that perform the specified functions or steps, or combinations of special purpose hardware and computer instructions.

This detailed description may refer to content items (which may also be referred to as “content,” “content data,” “content information,” “content asset,” “multimedia asset data file,” or simply “data” or “information”). Content items can comprise any information or data that may be licensed to one or more individuals (or other entities, such as business or group). In various examples, content may include electronic representations of video, audio, text and/or graphics, which may include but is not limited to electronic representations of videos, movies, or other multimedia, which may include but is not limited to data files adhering to MPEG2, MPEG, MPEG4 UHD, HDR, 4k, Adobe® Flash® Video (.FLV) format or some other video file format whether such format is presently known or developed in the future. In various examples, the content items described herein may include electronic representations of music, spoken words, or other audio, which may include but is not limited to data files adhering to the MPEG-1 Audio Layer 3 (.MP3) format, Adobe®, CableLabs 1.0,1.1, 3.0, AVC, HEVC, H.264, Nielsen watermarks, V-chip data and Secondary Audio Programs (SAP). Sound Document (.ASND) format or some other format configured to store electronic audio whether such format is presently known or developed in the future. In some cases, content may include data files adhering to the following formats: Portable Document Format (.PDF), Electronic Publication (.EPUB) format created by the International Digital Publishing Forum (IDPF), JPEG (.JPG) format, Portable Network Graphics (.PNG) format, dynamic ad insertion data (.csv), Adobe® Photoshop® (.PSD) format or some other format for electronically storing text, graphics and/or other information whether such format is presently known or developed in the future. In some examples, content items may include any combination of the above-described examples.

This detailed disclosure may refer to consuming content or to the consumption of content, which may also be referred to as “accessing” content, “providing” content, “viewing” content, “listening” to content, “rendering” content, or “playing” content, among other things. In some cases, the particular term utilized may be dependent on the context in which it is used. For example, consuming video may also be referred to as viewing or playing the video. In another example, consuming audio may also be referred to as listening to or playing the audio.

Note that this detailed disclosure may refer to a given entity performing some action. It should be understood that this language may in some cases mean that a system (e.g., a computer) owned and/or controlled by the given entity is actually performing the action.

The present disclosure relates to method and systems to detect rogue (e.g., unauthorized, illegitimate, untrusted, spoofing, etc.) network hotspots (e.g., access points). Additionally, the method and systems disclosed can detect compromised access points, such as authorized access points that associated with identifier information (e.g., SSID, MAC address, etc.) that has been copied by a rogue hotspot. A network can comprise a plurality of authorized network access points (e.g., access points authorized to be in communication with the network) that enable devices to be in communication with other devices and/or the network via the network. Rogue hotspots can be unauthorized (e.g., illegitimate, untrusted, spoofing, etc.) network access points, controlled by a malicious entity and/or person, masquerading as authorized network access points. The unauthorized access points may not be an actual access point; instead the unauthorized access point can be a wireless device such as a smartphone, laptop, tablet, computer, mobile computing device, and the like, for example. The unauthorized access point can masquerade as an authorized (e.g., legitimate, trusted, etc.) access point to trick a device/user into being in communication with and/or connecting to the unauthorized access point. For example, the unauthorized access point can masquerade as an authorized access point by using identifier information (e.g., a service set identifier (SSID), a media access control (MAC) address, a name, etc.) that is a copy (e.g., an exact copy, a similarity, a resemblance) of identifier information associated with the authorized access point. A device (e.g., user device, mobile device, network device, etc.) attempting to connect to/be in communication with the network via the authorized access point can actually be in communication with the unauthorized access point. The device can be unaware that it is in communication with the unauthorized access point. The device can transmit and/or receive data/information via the unauthorized access point. The unauthorized access point can obtain sensitive information associated with the device (e.g., user information, personal information, credit card information, login credentials, etc.) and/or take other negative actions (e.g., malware installation) that harm the device and/or a user of the device.

One or more authorized (e.g., legitimate, trusted, etc.) access points of the plurality of authorized access points can detect the unauthorized (e.g., illegitimate, untrusted, etc.) access point. The one or more authorized access points can detect the unauthorized access point by determining that a signal strength (e.g., received signal strength indication (RSSI)) associated with another authorized access point does not coincide with a predetermined signal strength for the another authorized access point. The signal strength associated with the another authorized access point not coinciding with the predetermined signal strength with which it is associated can indicate that identifier information (e.g., a SSID, a MAC address, etc.) associated with the another authorized access point has been copied by an unauthorized access point. An authorized access point associated with identifier information that has been copied by an unauthorized access point is a compromised access point.

Each authorized access point of the plurality of authorized access points can keep track of other authorized access points in proximity by periodically probing/scanning the network. During periodic probes/scans of the network, each authorized access point of the plurality of authorized access points can gather information associated with other authorized access points. The information associated with the other authorized access points can include identifier information (e.g., a SSID, a MAC address, etc.) and other information such as baseline (e.g., routine, consistent, etc.) signal strength (e.g., received signal strength indication (RSSI)) information, RSSI measurements, a name, combinations thereof, and the like. Each of the one or more authorized access points can store the identifier information and any other information associated with the other authorized access points. Further, each of the one or more authorized access points can transmit identifier information (e.g., identifier information associated with other authorized access points) or any other information to a computing device, such as a server/cloud-based device for example. The computing device can determine a confidence level associated with a determination by authorized access points that another authorized access point is a compromised access point (e.g., an authorized access point associated with identifier information that has been copied by an unauthorized access point). The computing device can determine the confidence level by comparing and/or reconciling identifier information associated with a particular authorized access point and received from each of the plurality of authorized access points. If the confidence level satisfies a threshold (e.g., a number of authorized access points providing the same and/or similar identifier information), the computing device can determine/verify that the identifier information associated with the particular authorized access point has been copied by an unauthorized access point and that the particular authorized access point is a compromised access point. The computing device can store the identifier information associated with the compromised access point. For example, the computing device can store the identifier information associated with the compromised access point as compromised identifier information. The computing device can store a record of any received identifier information determined to be compromised by an unauthorized access point in a database comprising a plurality of compromised identifier information.

Based on a determination that a compromised access point exists in the network (and/or that an unauthorized access point exists in the network), actions can be taken to neutralize the effect of the unauthorized access point in the network. Information (e.g., a message, code, etc.) can be sent to the compromised access point that causes the compromised access point to deauthenticate/disassociate devices (e.g., user devices, mobile devices, network devices, etc.) in communication and/or associated with the compromised access point. For example, a message (e.g., a deuthentication frame, etc.) can be sent to the compromised access point that causes the compromised access point to deauthenticate/disassociate devices in communication and/or associated with the compromised access point based on a SSID and/or MAC address associated with the compromised access point. Information (e.g., a message, code, etc.) can be sent to the to the compromised access point that causes the compromised access point to change/modify its associated identifier information. For example, a message can be sent to the compromised access point that causes the compromised access point to change a SSID and/or MAC address with which it is associated with to a new SSID and/or MAC address. The unauthorized access point will be unaware of the new identifier information. For example, the unauthorized access point will be unaware of the new SSID and/or MAC address associated with the previously compromised access point that is now (again) an authorized access point based on the new identifier information. Devices that were previously connected to/in communication with the previously compromised access point can reconnect, re-associate with, and/or be in communication with the previously compromised access point that is now (again), based on the new identifier information, an authorized access point.

1 FIG. Disclosed is a system to detect rogue hotspots (e.g., unauthorized access points, illegitimate access points, untrusted access points, etc.). Additionally, the system disclosed can detect compromised access points, such as authorized access points that are associated with identifier information (e.g., SSID, MAC address, etc.) that has been copied by a rogue hotspot.depicts an example environment in which the present methods and systems can operate. The present disclosure is relevant to systems and methods for providing unauthorized access point detection services. One or more network devices can be configured to provide various services to one or more devices, such as wireless communication services and unauthorized access point detection services. The network devices can be configured to recognize an authoritative device for a premises (e.g., local network) and/or a wide area network. As an example, an authoritative device (e.g., authorized access point, network device, computing device, server, cloud-based device, etc.) can be configured to govern or enable connectivity to a network such as the Internet or other remote resources, provide address and/or configuration services such as service set identifier (SSID) configuration, media access control (MAC) address configuration, DHCP, and/or provide naming or service discovery services for a premises, wide area network or a combination thereof. Those skilled in the art will appreciate that present methods may be used in various types of networks and systems that employ both digital and analog equipment. One skilled in the art will appreciate that provided herein is a functional description and that the respective functions can be performed by software, hardware, or a combination of software and hardware.

102 105 116 116 102 116 116 104 104 102 116 116 105 a b, a b a b. The network and system can comprise a user device(e.g., a mobile communication device, a computer, a smartphone, a laptop, a tablet, a set top box, a display device, etc.) in communication with a networkvia a network device (e.g., access point, authorized access point, legitimate access point, trusted access point, etc.). The network and system can comprise a plurality of network devices such as network devicesandfor example. The user deviceand/or the network devicesandcan be in communication with a computing device(e.g., a server, a network device, a computer, a cloud-based device, etc.). The computing devicecan be disposed locally or remotely relative to the user deviceand/or network devicesandThe networkcan comprise one or more networks, such as a wide area network (e.g., a content network, service network, provider network, the Internet), a public network, an open network, a provider managed network, a non-user managed network, a provider controlled network, a non-user controlled network, a local network, a private network, a closed network, a user managed network, a user controlled network, a user deployed network, and/or the like. Other forms of communications can be used, such as wired and wireless telecommunication channels, for example.

102 102 106 102 116 116 104 106 102 116 116 104 106 106 106 104 a b, a b, The user devicecan be a communication device, such as a computing device. For example, the user devicecan comprise a communication elementfor providing an interface to a user to interact with the user device, network devicesandand/or the computing device. The communication elementcan be any interface for presenting information to the user and receiving a user feedback, such as an application client or a web browser (e.g., Internet Explorer, Mozilla Firefox, Google Chrome, Safari, or the like). Other software, hardware, and/or interfaces can be used to provide communication between the user and one or more of the user device, the network devicesandand/or the computing device. As an example, the communication elementcan request or query various files from a local source and/or a remote source. As an example, the communication elementcan receive various files from a local source and/or a remote source. As a further example, the communication elementcan transmit data to and/or receive data from a local or remote device, such as the computing device.

102 108 108 102 108 108 102 102 108 The user devicecan be associated with a user identifier or device identifier. As an example, the device identifiercan be any identifier, token, character, string, or the like, for differentiating one user and/or user device (e.g., user device) from another user or user device. The device identifiercan identify a user or user device as belonging to a particular class of users or user devices. As a further example, the device identifiercan comprise information relating to the user device, such as a manufacturer, a model or type of device, a service provider associated with the user device, a state of the user device, a locator, and/or a label or classifier. Other information can be represented by the device identifier.

108 110 112 110 110 102 104 110 102 110 The device identifiercan comprise an address elementand/or a service element. The address elementcan be an internet protocol address, a MAC address, a network address, an Internet address, or the like. As an example, the address elementcan be relied upon to establish a communication session between the user deviceand the computing deviceor other devices and/or networks. As a further example, the address elementcan be used as an identifier or locator of the user device. The address elementcan be persistent for a particular network and/or location.

112 102 102 112 102 112 102 110 112 110 112 102 102 104 112 The service elementcan comprise an identification of a service and/or service provider associated with the user deviceand/or with the class of user device. As an example, the service elementcan comprise information relating to or provided by a communication service provider (e.g., Internet service provider) that is providing or enabling communication services to the user device. As a further example, the service elementcan comprise information relating to a preferred service provider for one or more particular services relating to the user device. The address elementcan be used to identify or retrieve the service element, or vice versa. As a further example, one or more of the address elementand the service elementcan be stored remotely from the user deviceand retrieved by one or more devices, such as the user deviceand the computing device. Other information can be represented by the service element.

102 118 119 116 116 102 116 118 116 119 118 119 116 116 a b a b a b. The user devicecan store identifier information (e.g., identifier information, identifier information). The identifier information can comprise information such as SSIDs, MAC addresses, passwords, security settings, combinations thereof, and the like associated with one or more networks and/or network devices (e.g., access points, authorized access points, network devicesand) to which the user deviceis authorized to connect. Each network device can be associated with identifier information. For example, the network devicecan be associated with identifier informationand the network devicecan be associated with identifier information. The identifier information (e.g., identifier information, identifier information) can comprise network credentials (e.g., SSID, MAC address, etc.) for accessing the network devicesand

118 119 102 116 116 105 116 116 102 105 116 116 116 116 116 116 118 116 116 116 116 116 116 118 119 118 119 116 116 118 a b a b a b a b a b a b a b a b a b The identifier information (e.g., identifier information, identifier information) can comprise a unique identifier for facilitating communications with devices such as user device, for example. Further, the network devicesandcan be in communication with a network, such as the network. For example, the network devicesandcan facilitate the connection of a device, such as the user device, to the network. As such, the network devicesandcan be configured as network gateways and/or access points. The network devicesandcan be configured to allow one or more wireless devices to connect to a wired and/or wireless network using Wi-Fi, Bluetooth or similar standard. The network devicesandcan be multi-band wireless network devices. The identifier informationcan comprise service set identifier (SSID) information. The SSID information can comprise basic service set identifier (BSSID) information, extended service set identifier (ESSID) information, combinations thereof, and the like. The network devicesandcan be configured with a first service set identifier (SSID) to function as a local network for a particular user or users (e.g., associated with a user network or private network). The network devicesandcan be configured with a second service set identifier (SSID) (e.g., associated with a public/community network, hidden network, or limited services (e.g., provisioning) network) to function as a secondary network or redundant network for connected communication devices. The network devicesandcan be accessed via identifier informationand, respectively. Further, the identifier information (e.g., identifier information, identifier information) can comprise information associated with the network devicesandsuch as the SSID (e.g., SSID, BSSID, ESSID, first SSID, second SSID, etc.) information, password information, security settings, communication signal information, combinations thereof, and the like. Some or all of the identifier informationcan be stored in an encrypted or hashed form.

116 116 104 104 115 115 116 116 115 115 104 104 116 116 102 117 104 116 116 102 104 104 130 116 116 a b a b a b a b a b, a b, a b The network devicesandcan be in communication with the computing deviceto provide the computing devicewith periodic identifier information (e.g., identifier information associated with authorized access points, identifier information associated with compromised access points, etc.) and/or any other information determined based on a periodic probe/scan,of the network. The network devicesandcan transmit identifier information (e.g., identifier information associated with authorized access points, identifier information associated with compromised access points, etc.) and/or any other information determined during a periodic probe/scan,to the computing device. The computing devicecan be a network device such as server/cloud-based device in communication with devices such as the network devicesandthe user device, and any other device for providing services such as unauthorized access point (e.g., rogue hotspot, rogue device) detection services. The computing devicecan allow the network devicesandthe user device, and any other device to interact with remote resources, such as data, devices, and files. For example, the computing devicecan be configured as central location (e.g., a headend, or processing facility), which can receive content (e.g., RSSI information, identifier information, data, input programming) from multiple sources. The computing devicecan combine the content (e.g., the master list) from the various sources (e.g., network devicesand) and can distribute the content to user (e.g., subscriber) locations, and or any other location via a distribution system.

104 116 116 102 114 116 116 102 114 114 116 116 102 118 110 112 116 102 130 a b, a b, a b The computing devicecan manage the communication between the network devicesandthe user device, any other device, and a databasefor sending and receiving data therebetween. For example, the network devicesandthe user device, and any other device can request and/or retrieve a file from the database. The databasecan store information relating to the network devicesand, the user device, and any other device (such as compromised identifier information, the identifier information, the address element, and/or the service element), information related to the network device, the user device, and any other device (such as RSSI information, identifier information associated with one or more network devices, master list, etc.).

116 116 118 116 116 104 116 116 116 116 118 118 116 116 116 116 104 116 116 116 116 116 116 102 116 116 116 116 118 a b a b a b a b a b. a b a b a b a b a b a b The network devicesandcan periodically transmit and/or broadcast at least a portion of the identifier information(e.g., MAC address, SSID, signal strength information, etc.) to other devices, such as another network device (e.g., network devicesand), the computing device, combinations thereof, and the like. Additionally, the network devicesandcan periodically transmit and/or broadcast additional information to the other devices. For example, the network devicesandcan periodically transmit and/or broadcast a beacon comprising the identifier informationand/or additional information. The beacon comprising the identifier informationcan be associated with a signal strength (e.g., a signal strength value, RSSI, etc.) associated with the network devicesandFor example, the beacon can inform other devices, such as another network device (e.g., network devicesand), the computing device, combinations thereof, and the like, that a signal strength associated with the network devicesandwas and/or is provisioned at a certain value (e.g., decibel value, amplitude value, power value, etc.). The provisioned value of a signal strength associated with a network device (e.g., network devicesand) can be a baseline (e.g., consistent, regular, routine, etc.) signal strength associated with a network device (e.g., network devicesand). Additionally, the beacon can also comprise information to facilitate a connection between the user deviceand the network devicesandsuch as an SSID. The beacon can be transmitted over one or more channels and/or frequency bands. The network devicesandcan transmit and/or receive multiple beacons that can comprise information such as all or at least a portion of the identifier information, additional information, and the like.

116 116 116 116 116 116 115 115 116 116 118 116 116 116 116 116 116 116 116 116 116 116 116 116 116 116 116 116 116 115 115 105 105 116 105 116 116 116 116 116 116 115 115 116 116 116 116 104 104 116 116 130 116 116 115 115 130 118 116 116 a b a b a b a, b, a b a b a b a b a b a b a b a b a b a b a, b a b. a b, a b a, b a b a b a b a b, a, b a b. The network devicesandcan determine a signal strength associated with another network device (e.g., network devicesand) based on measuring a value (e.g., decibel value, amplitude value, power value, integrity value, etc.) associated with the received beacon(s). For example, network devicesandcan receive, during a periodic probe/scana beacon from another network device (e.g., network devicesand). The beacon can comprise an identifier (e.g., identifier information) associated with the other network device (e.g., network devicesand). The network devicesandcan determine that the beacon is associated with the other network device (e.g., network devicesand) based on the identifier. The beacon can comprise a signal strength indicator (e.g., RSSI). The network devicesandcan determine a signal strength associated with the other network device (e.g., network devicesand) based on a received signal strength indicator (RSSI) measurements associated with the other network device (e.g., network devicesand). The network devicesandcan determine a baseline signal strength associated with the other network device (e.g., network devicesand) based on/by measuring a received signal strength indicator (RSSI) associated with the other network device (e.g., network devicesand). For example, during a probe/scan(e.g., an initial probe/scan) of the networkto determine network devices in the network(e.g., network device discovery, access point discovery, etc.) an initial list of network devices (e.g., network device, access points, etc.) in communication with the networkcan be is generated by the network devicesandA received signal strength indication (RSSI) for each of the network devices (e.g., network devicesandaccess points, etc.) on/in the initial list can be measured and stored as a baseline signal strength associated with each of the network devices (e.g., network devicesand). The initial list and/or any other related list (e.g., a list created based on a periodic probe/scanof the network) can be stored by the network devicesandor by another device. For example, the network devicesandcan transmit the initial list (or any other related list) to the computing device. The computing devicecan receive initial lists (or any other related lists) from a plurality of network devices (e.g., network devicesand) and generate/store/update a master listcomprising the received lists (or any other related lists). The list (e.g., initial list or any other related list) can be updated with new RSSI measurements associated with network devices (e.g., network devicesandaccess points, etc.) based on periodic probes/scansof the network. The initial list, the master list, and/or any related list can comprise information (e.g., identifier information, identifier information, discovery information, provisioning information, etc.) associated with the RSSI measurements/information determined from each of the network devicesand

116 116 117 105 117 116 116 117 116 118 116 117 116 118 116 118 102 125 117 118 116 102 117 116 116 117 105 116 115 a b a b, a, a a a a. a. b b b. The network devicesandcan detect a device, such as rogue device(e.g., rogue hotspot, unauthorized access point, etc.), that is not authorized to provide communication to and/or be in communication with the network. For example, the rogue devicecan be a device such as a smartphone, laptop, tablet, computer, mobile computing device, and the like, configured to mimic a network device (e.g., network devicesandauthorized access point, etc.). The rogue devicecan mimic a network device (e.g., network deviceauthorized access point, etc.) by copying and broadcasting/transmitting a beacon comprising identifier information (e.g., identifier information) associated with the network device (e.g., network device). For example, the rogue devicecan mimic the network deviceby copying identifier informationwhich comprises information such as a MAC address and/or SSID associated with the network deviceand storing the identifier information. One or more devices (e.g., user device) can be in communicationwith the rogue devicebased on the identifier information(e.g., copied identifier information) associated with the network deviceThe one or more devices (e.g., user device) can be unaware that they are in communication with the rogue deviceinstead of a network deviceThe network devicecan determine/detect that the rogue deviceis present in the networkbased on one or more received signal strength indicators (RSSIs) associated with the network devicedetermined during a periodic probe/scan

116 116 117 105 115 115 105 116 116 115 115 105 116 116 115 115 105 105 105 116 116 117 116 116 105 105 116 116 115 115 105 105 105 a b a b a b a b a b a b a b, a b a b a b The network devicesandcan determine/detect that the rogue deviceis present in the networkbased on one or more received signal strength indicators (RSSIs) received during a periodic probe/scanandof the network. The network devicesandcan periodically probe/scanandthe networkfor a time window (e.g., 20 microseconds). The network devicesandcan periodically probe/scanandthe networkfor a time widow/time period, such as of 20 microseconds, and determine information associated with the networkand or devices in communication with the network(e.g., network devicesandrogue device, etc.). The network devicesandcan determine the information associated with the networkand or devices in communication with the networkbased on information received during the time window. For example, the network devicesandcan periodically probe/scanandthe networkfor a time window of 20 microseconds and determine information associated with the networkand or devices in communication with the networksuch as a value of a received signal strength indicator (RSSI).

116 116 116 116 116 116 117 116 116 115 115 105 116 116 60 116 116 116 116 a b a b a b a b a b a b a b, a b The network devicesandcan determine, based on the RSSI value, if a device (e.g., network devicesand) associated with the RSSI and/or identifier information is a device (e.g., network devicesand) that should be associated with the RSSI and/or identifier information or a rogue device (e.g., rogue hotspot, unauthorized access point, etc.), such as rogue device. For example, the network devicesandcan determine from the periodic probe/scanand(e.g., an initial probing/scanning) of the networkthat an RSSI associated with another network device (e.g., network devicesand) is routinely and/or consistentlydecibels (dB). A list (e.g., initial list) of network devices (e.g., network devicesandauthorized access points, etc.) can comprise information (e.g., discovery information, provisioning information, etc.) detailing that the RSSI associated with the other network device (e.g., network devicesand) is routinely and/or consistently 60 dB.

116 116 116 116 116 116 60 115 115 105 116 116 116 116 116 116 116 116 116 116 a b a b a b a b a b a b a b a b a b The network devicesandcan determine that an RSSI associated with the other network device (e.g., network devicesand) varies within a threshold from the information detailing that the RSSI associated with the other network device (e.g., network devicesand) is routinely and/or consistently 60 dB (e.g., a baseline RSSI ofdB). For example, during a periodic probe/scan (e.g., periodic probe/scanand) of the network, the network devices (e.g., network devicesand) can take/determine multiple RSSI measurements associated with the other network device (e.g., network devicesand). The network device (e.g., network devicesand) can determine that the multiple RSSI measurements associated with the other network device (e.g., network devicesand) taken during the time window are of a certain value such as 59 dB, 58 dB, etc. The network devices (e.g., network devicesand) can determine that the multiple RSSI measurements do not exceed a threshold variance from 60 dB. The threshold variance can be, for example, +/−1 dB, 2 dB, 3 dB, 4 dB, 5 dB, 6 dB, 7 dB, 8 dB, 9 dB, 10 dB, 11 dB, 12 dB, 13 dB, 14 dB, 15 dB, 16 dB, 17 dB, 18 dB, 19 dB, 20 dB, 21 dB, 22 dB, 23 dB, 24 dB, 25 dB, and the like. One of skill in the art will appreciate that other threshold variances can be used and can vary depending on what measurement is used.

116 116 116 116 116 116 116 116 116 116 116 116 119 117 116 116 117 105 116 116 118 117 a b a b. a b a b a b a b a b a b The number of multiple RSSI measurements taken/determined can be manually provisioned. For example, the network devicesandcan be manually configured to take five RSSI measurements, ten RSSI measurements, twenty RSSI measurements, or any number of RSSI measurements during the time window. Additionally, the number of RSSI measurements taken/determined can be dynamically determined by the network devicesandFor example, the network devicesandcan automatically determine any number of RSSI measurements to take/determine during the time window. A threshold variance value can be set at any value deviation from baseline signal strength, for example, +/−1 dB, 2 dB, 3 dB, 4 dB, 5 dB, 6 dB, 7 dB, 8 dB, 9 dB, 10 dB, 11 dB, 12 dB, 13 dB, 14 dB, 15 dB, 16 dB, 17 dB, 18 dB, 19 dB, 20 dB, 21 dB, 22 dB, 23 dB, 24 dB, 25 dB, and the like. One of skill in the art will appreciate that other threshold variances can be used and can vary depending on what measurement is used. Based on the multiple RSSI measurements not exceeding the threshold variance, the network devicesandcan determine that the other network device (e.g., network devicesand) is not compromised. The other network device is not compromised if the identifier information associated with the other network device (e.g., network devicesand) has not been copied (e.g., identifier information) by the rogue device. The network devicesandcan determine, based on the other network device not being compromised, that the rogue deviceis not present in the network. The other network device is compromised if the identifier information associated with the other network device (e.g., network devicesand) has been copied (e.g., identifier information) by the rogue device.

117 117 115 115 116 116 117 116 116 116 118 117 116 116 116 118 117 a b. a b a b a a b a The rogue devicecan be associated with an RSSI that is inconsistent in value, fluctuates, and/or exhibits erratic behavior during the time window. For example, the rogue devicecan be associated with an RSSI that changes in value from 60 dB to 30 dB within a time widow associated with a periodic probe/scanandThe changes in value from 60 dB to 30 dB within the time widow can exceed a threshold variance from 60 dB. A threshold variance value can be set at any value deviation from baseline signal strength, The threshold variance can be, for example, +/−1 dB, 2 dB, 3 dB, 4 dB, 5 dB, 6 dB, 7 dB, 8 dB, 9 dB, 10 dB, 11 dB, 12 dB, 13 dB, 14 dB, 15 dB, 16 dB, 17 dB, 18 dB, 19 dB, 20 dB, 21 dB, 22 dB, 23 dB, 24 dB, 25 dB, and the like from the baseline signal strength. One of skill in the art will appreciate that other threshold variances can be used and can vary depending on what measurement is used. The network devicesandcan determine, based on the RSSI associated with the rogue devicenot coinciding/reconciling with the information (e.g., discovery information, provisioning information, etc.) associated with the other network device (e.g., network devicesand) stored in an initial list (or any other list), that the identifier information associated with the other network device (e.g., network device) has been copied (e.g., identifier information) by the rogue device. The network devicesandcan determine, based on RSSI measurements exceeding the threshold variance, that the other network device is compromised. The other network device is compromised if the identifier information associated with the other network device (e.g., network devices) has been copied (e.g., identifier information) by the rogue device.

116 116 116 116 116 116 116 116 104 104 114 116 116 116 118 115 115 104 116 116 104 116 116 115 115 104 130 a b a b a b a b a b a b a b a b a b The network devicesandcan store the identifier information associated with the other network device (e.g., network devicesand) as compromised identifier information. The network devicesandcan transmit the identifier information associated with the other network device (e.g., network devicesand) to another device, such as the computing device, for example. The computing deviceand/or any other device can store (e.g., in database) the identifier information associated with the other network deviceas compromised identifier information. The network devicesandcan transmit the compromised identifier information (e.g., identifier information) and/or any other information determined from a periodic probe/scanandto the computing device. The network devicesandcan transmit the compromised identifier information and/or any other information determined from a periodic probe/scan to the computing deviceperiodically (e.g., every hour, every day, etc.). The network devicesandcan transmit the compromised identifier information and/or any other information determined from a periodic probe/scanandto the computing deviceto update the master list.

104 118 116 116 102 104 118 114 130 116 116 115 115 118 114 114 104 114 104 116 116 102 116 116 a b, a b a b a b a b The computing devicecan receive information (e.g., the compromised identifier information, identifier information) from the network devicesandthe user device, and any other device. The computing devicecan retrieve information (e.g., the identifier information, compromised identifier information, etc.) from and/or store information in the database(e.g., the master list), such as RSSI information determined by network devices (e.g., network devicesand) during a periodic probe/scan (e.g., periodic probe/scanand), identifier information (e.g., identifier information), combinations thereof, and the like. Any information can be stored in and retrieved from the database. The databasecan be disposed remotely from the computing deviceand accessed via direct or indirect connection. The databasecan be integrated with the computing deviceor some other device (e.g., network devicesand) or system. The computing device may be configured as other devices, such as a user device (e.g., user device) or a network device (e.g., network devicesand), for example.

104 118 116 104 114 130 116 116 b a b The computing devicecan receive the compromised identifier information (e.g., identifier information) from the network devices (e.g., network device). The computing devicecan store the compromised identifier information in a database (e.g., database) and/or generate/update a list (e.g., master list) comprising identifier information and/or compromised identifier information associated with a plurality of network devices (e.g., network devicesand).

104 116 117 105 104 105 116 116 115 115 105 104 104 105 a, a b, a b The computing devicecan determine that a compromised network device (e.g., network devicecompromised access point, etc.), and/or that a rogue device (e.g., rogue device, rogue hotspot, unauthorized access point, etc.), exists in the network. The computing devicecan determine that a compromised network device and/or a rogue device exists in the networkbased on information, such as signal strength information (e.g., measured signal strength information, RSSI information, etc.) received from a plurality of authorized network devices (e.g., network devicesandauthorized access points, etc.). For example, each authorized network device of the plurality of authorized network devices can transmit/provide signal strength information determined during a periodic probe/scan (e.g., periodic probe/scanand) of the networkto the computing device. The computing devicecan analyze the signal strength information received from each authorized network device of the plurality of authorized network devices to determine that a compromised network device and/or a rogue device exists in the network.

104 104 104 104 104 104 The computing devicecan summate (e.g., average) signal strength information associated with a particular authorized network device that is received from multiple authorized network devices. The computing devicecan determine that the signal strength information received from multiple authorized network devices is associated with the particular authorized network device based on network identifier information associated with the particular authorized network device received with the signal strength information from the multiple authorized network devices. The computing devicecan determine a baseline signal strength associated with the particular authorized network device by summating (e.g., averaging) the signal strength information received from the multiple authorized network devices. For example, a first authorized network device can transmit signal strength information associated with the particular authorized network device that informs the computing devicethat the signal strength associated with the particular authorized network device is 70 dB, and a second authorized network device can transmit signal strength information associated with the particular authorized network device that informs the computing devicethat the signal strength associated with the particular authorized network device is 68 dB. The computing devicecan summate or average the signal strength information received from the first authorized network device and the signal strength information received from the second authorized network device to determine that a baseline signal strength associated with the particular authorized network device is 69 dB (e.g., an average of 70 dB and 68 dB).

104 104 104 8 The computing devicecan determine whether the particular authorized network device is compromised based on a difference between the baseline signal strength associated with the particular authorized network device and subsequent signal strength measurements associated with the particular authorized network device received from the multiple authorized network devices (e.g., the first authorized network device, and the second authorized network device). If the difference between the baseline signal strength associated with the particular authorized network device and a summation or an average of the subsequent signal strength measurements associated with the particular authorized network device received from the multiple authorized network devices does not exceed a threshold variance from 69 dB, then the computing devicecan determine that the particular authorized network device is not compromised. If the difference between the baseline signal strength associated with the particular authorized network device and a summation or an average of the subsequent signal strength measurements associated with the particular authorized network device received from the multiple authorized network devices exceed a threshold variance from 69 dB, then the computing devicecan determine that the particular authorized network device is compromised. The threshold variance can be, for example, +/−1 dB, 2 dB, 3 dB, 4 dB, 5 dB, 6 dB, 7 dB,dB, 9 dB, 10 dB, 11 dB, 12 dB, 13 dB, 14 dB, 15 dB, 16 dB, 17 dB, 18 dB, 19 dB, 20 dB, 21 dB, 22 dB, 23 dB, 24 dB, 25 dB, and the like. One of skill in the art will appreciate that other threshold variances can be used and can vary depending on what measurement is used.

104 116 117 105 116 115 105 104 104 105 a, b, b Additionally, the computing devicecan determine that a compromised network device (e.g., network devicecompromised access point, etc.) and/or that a rogue device (e.g., rogue device, rogue hotspot, unauthorized access point, etc.) exist in the networkbased on information, such as signal strength information (e.g., measured signal strength information, RSSI information, etc.) received from a single authorized network device (e.g., network deviceetc.). For example, the authorized network device can transmit/provide signal strength information determined during a periodic probe/scan (e.g., periodic probe/scan) of the networkto the computing device. The computing devicecan analyze the signal strength information received from the authorized network device to determine that a compromised network device and/or a rogue device exist in the network.

104 104 104 The computing devicecan receive signal strength information associated with a particular authorized network device from the authorized network device. The computing devicecan determine that the signal strength information received from the authorized network device is associated with the particular authorized network device based on network identifier information associated with the particular authorized network device received with the signal strength information from the authorized network device. The computing devicecan store the signal strength information associated with a particular authorized network device received from the authorized network device as a baseline signal strength associated with the particular authorized network device.

104 104 104 4 8 The computing devicecan determine whether the particular authorized network device is compromised based on a difference between the baseline signal strength associated with the particular authorized network device and subsequent signal strength measurements associated with the particular authorized network device received from the authorized network device. If the difference between the baseline signal strength associated with the particular authorized network device and subsequent signal strength measurements associated with the particular authorized network received from the authorized network device does not exceed a threshold variance, then the computing devicecan determine that the particular authorized network device is not compromised. If the difference between the baseline signal strength associated with the particular authorized network device and subsequent signal strength measurements associated with the particular authorized network received from the authorized network device exceeds a threshold variance, then the computing devicecan determine that the particular authorized network device is compromised. The threshold variance can be, for example, +/−1 dB, 2 dB, 3 dB,dB, 5 dB, 6 dB, 7 dB,dB, 9 dB, 10 dB, 11 dB, 12 dB, 13 dB, 14 dB, 15 dB, 16 dB, 17 dB, 18 dB, 19 dB, 20 dB, 21 dB, 22 dB, 23 dB, 24 dB, 25 dB, and the like. One of skill in the art will appreciate that other threshold variances can be used and can vary depending on what measurement is used.

116 117 105 105 116 102 104 116 116 116 125 118 116 118 116 118 117 116 102 116 a a a, b, a a a a a Based on a determination that a compromised network device (e.g., network device, compromised access point, etc.) and/or that a rogue device (e.g., rogue device, rogue hotspot, unauthorized access point, etc.) exist in the network, actions can be taken to neutralize the effect the unauthorized access point in the network. Information (e.g., a message, code, etc.) can be sent to the to the compromised network device (e.g., network device) that causes the compromised network device to deauthenticate/disassociate devices (e.g., user device, mobile devices, network devices, etc.) in communication and/or associated with the compromised access point. The message can be sent by a device such as the computing device, the network devicethe network device,combinations thereof, and the like. For example, a message (e.g., a deuthentication frame, etc.) can be sent to the compromised network device (e.g., network device) that causes the compromised network device to deauthenticate/disassociate devices in communication (e.g., communication) and/or associated with the compromised network device based on identifier information (e.g., identifier information). Information (e.g., a message, code, etc.) can be sent to the to the compromised network device (e.g., network device) that causes the compromised network device to change/modify its identifier information (e.g., identifier information). For example, a message can be sent to the compromised network device (e.g., network device) that causes the compromised network device to change identifier information (e.g., identifier information) to which it is associated with to a new identifier information (e.g., a new SSID, a new MAC address, etc.). The rogue device (e.g., rogue device, rogue hotspot, unauthorized access point, etc.) will be unaware of the new identifier information. For example, the rogue device will be unaware of the new SSID and/or MAC address associated with the previously compromised network device (e.g., network device) that is now (again) an authorized network device based on the new identifier information. Devices (e.g., user device) that were previously connected to/in communication with the previously compromised network device (e.g., network device) can reconnect, re-associate with, and/or be in communication with the previously compromised network device that is now (again), based on the new identifier information, an authorized network device.

2 FIG. 117 116 116 200 201 202 203 204 201 202 203 202 201 203 203 201 202 a b, is an example system in which the present methods and systems can operate. The system details the effect of a rogue access point (e.g., rogue device, rogue hotspot, unauthorized access point, illegitimate access point, untrusted access point, etc.) on received signal strength indicators (RSSIs) associated with a plurality of access points (e.g., network devicesandauthorized access points, legitimate access points, trusted access points, etc.). A systemcan comprise access points,, andand a rogue access point. Any of the steps, methods, actions, and the like performed by the access pointcan be performed by the access pointand/or the access point. Any of the steps, methods, actions, and the like performed by access pointcan be performed by the access pointand/or the access point. Any of the steps, methods, actions, or the like performed by the access pointcan be performed by the access pointand/or access point.

201 118 119 201 205 206 202 203 201 205 206 118 119 201 202 203 202 205 202 201 203 203 205 207 203 201 202 The access pointcan periodically and/or consistently transmit/broadcast a beacon comprising identifier information (e.g., identifier information, identifier information, etc.) such as a media access control (MAC) address, service set identifier (SSID) information, combinations thereof, and the like, for example. The access pointcan receive a one or more beacons, andfrom the access pointsand, respectively. The access pointcan transmit/broadcast a beacon (e.g.,and) comprising identifier information (e.g., identifier information, identifier information, etc.) such as a MAC address (e.g., MAC address 00:00:01), service set identifier (SSID) information (not shown), combinations thereof, and the like associated with the access pointthat is received by one or more of the access point, the access point, combinations thereof, and the like. The access pointcan transmit/broadcast a beacon (e.g.,) comprising identifier information such as a MAC address (e.g., MAC address 00:00:02), service set identifier (SSID) information (not shown), combinations thereof, and the like associated with the access pointthat is received by one or more of the access point, the access point, combinations thereof, and the like. The access pointcan transmit/broadcast a beacon (e.g.,and) comprising identifier information such as a MAC address (e.g., MAC address 00:00:03), service set identifier (SSID) information (not shown), combinations thereof, and the like associated with access pointthat is received by one or more of the access point, the access point, combinations thereof, and the like.

201 202 203 205 206 207 115 115 200 205 206 207 201 202 203 201 200 202 203 206 205 202 203 201 200 202 203 206 205 202 203 a b The access points,, andcan receive the beacons (e.g.,,, and) during periodic probes/scans (e.g., periodic probes/scansand) of the system. Each of the beacons (e.g.,,, and) can comprise and/or be associated with a received signal strength indicator (RSSI). The access points,, andcan measure/determine a value of each RSSI associated with each beacon received. For example, the access pointcan perform a periodic probe/scan of the systemto determine/detect the presence access pointsandbased in a RSSI value determined from the beacons (e.g.,and) received from the access pointsand, respectively. For example, the access pointcan periodically probe/scan the systemfor a time window (e.g., 20 microseconds) and determine/measure multiple RSSI values then sum and/or average multiple RSSI values received from the access pointsandas the beaconsand, respectively and determine baseline RSSI values associated with the access pointand access point.

201 202 206 202 201 206 202 118 202 201 203 205 202 201 205 203 118 203 201 202 203 202 203 208 200 201 208 104 114 130 202 203 208 202 202 209 203 210 The access pointcan determine a baseline RSSI value of 60 (e.g., 60 decibels) associated with the access pointbased on one or more beacons (e.g., beacon) received from the access pointduring the time window. The access pointcan determine that the one or more beacons (e.g., beacon) received during the time window are associated with/from the access pointbased on identifier information such as MAC address 00:00:02, identifier information, service set identifier (SSID) information, combinations thereof, and the like associated with the access pointand received along with the one or more beacons. The access pointcan determine a baseline RSSI value of 70 (e.g., 70 decibels) associated with the access pointbased on one or more beacons (e.g., beacon) received from the access pointduring the time window. The access pointcan determine that the one or more beacons (e.g., beacon) received during the time window are associated with/from access pointbased on identifier information such as MAC address 00:00:03, identifier information, service set identifier (SSID) information, combinations thereof, and the like associated with the access pointand received along with the one or more beacons. The access pointcan store the identifier information associated with access pointand access pointalong with the respective baseline RSSI values associated with the access pointand the access pointas a list/tablein order to track access points in communication with the system. The access pointcan transmit the list/tableto another device (e.g., computing device) to store be stored by the device in a database (e.g., database) and/or list (e.g., master list) associated with access points. Access pointand access pointcan create/generate a similar list/table as the list/tablein the same manner as described for access point. For example, access pointcan create/generate a similar list/tableand the access pointcan create/generate a similar list/table.

201 202 202 205 201 202 201 201 201 201 202 202 201 204 117 The access pointcan determine that an RSSI value associated with access pointvaries within a threshold from the baseline RSSI value (e.g., RSSI=60) associated with access pointreceived with beacon(s). For example, during a periodic probe/scan access pointcan determine multiple RSSI measurements associated with the access pointduring the time window are values, such as 59 dB, 58 dB, etc. and determine that the multiple RSSI measurements do not exceed a threshold variance from 60 dB. The number of multiple RSSI measurements taken/determined can be manually provisioned. For example, the access pointcan be manually configured to take 5, 10, 20, or any number of RSSI measurements during the time window. The number of RSSI measurements taken/determined can be dynamically determined by the access point. For example, the access pointcan automatically determine any number of RSSI measurements to take/determine during the time window. A threshold variance value can be set at any suitable value, for example, +/−1 dB, 2 dB, 3 dB, 4 dB, 5 dB, 6 dB, 7 dB, 8 dB, 9 dB, 10 dB, 11 dB, 12 dB, 13 dB, 14 dB, 15 dB, 16 dB, 17 dB, 18 dB, 19 dB, 20 dB, 21 dB, 22 dB, 23 dB, 24 dB, 25 dB, and the like. One of skill in the art will appreciate that other threshold variances can be used and can vary depending on what measurement is used. Based on the multiple RSSI measurements not exceeding the threshold variance, the access pointcan determine that the access pointis not compromised. The access pointis not compromised if the identifier information associated with the access point(e.g., MAC address 00:00:02) has not been copied by another device (e.g., rogue access point, rogue device, rogue hotspot, unauthorized access point, etc.).

202 201 203 70 203 206 201 203 During a probe/scan of the system, the access pointcan determine that an RSSI value associated with access pointvaries within a threshold from the baseline RSSI value (e.g., RSSI =) associated with access pointreceived with beacon(s). For example, during the probe/scan access pointcan determine multiple RSSI measurements associated with the access pointduring the time window are values, such as 69 dB, 68 dB, etc. and determine that the multiple RSSI measurements do not exceed a threshold variance from 70 dB. A threshold variance value can be set at any suitable value, for example, +/−1 dB, 2 dB, 3 dB, 4 dB, 5 dB, 6 dB, 7 dB, 8 dB, 9 dB, 10 dB, 11 dB, 12 dB, 13 dB, 14 dB, 15 dB, 16 dB, 17 dB, 18 dB, 19 dB, 20 dB, 21 dB, 22 dB, 23 dB, 24 dB, 25 dB, and the like. One of skill in the art will appreciate that other threshold variances can be used and can vary depending on what measurement is used.

202 201 203 203 70 200 204 204 204 117 118 119 203 204 102 203 204 102 203 204 208 118 201 206 207 200 During a subsequent probe/scan of the system, the access pointcan determine that an RSSI value associated with access pointexceeds the variance threshold. RSSI readings (e.g., the baseline RSSI) associated with the access pointcan be steady and/or consistent, such as a RSSI value of, for example. The systemcan comprise the rogue access point. The rogue access pointmay not be an actual access point. The rogue access pointcan be a device (e.g., rogue device, smartphone, laptop, tablet, computer, mobile computing device, etc.) set up by malicious entity that copies and/or assigns similar identifier information (e.g., MAC address 00:00:03, identifier information, service set identifier (SSID) information, copied identifier information) as an access point (e.g., access point). The rogue access pointcan be set up by the malicious entity to obtain sensitive information (e.g., user information, personal information, credit card information, login credentials, etc.) associated with a device (e.g., user device) in communication with the access point. The rogue access pointcan be set up by the malicious entity to take other negative actions (e.g., malware installation) that harm the device (e.g., user device). The copied identifier information can comprise information such the MAC address (e.g., MAC address 00:00:03) and service set identifier (SSID) associated with the access point. The rogue access pointcan periodically and/or consistently transmit/broadcast one or more beaconscomprising the copied identifier information (e.g., identifier information) and a received signal strength indicator (RSSI). The access pointcan receive the one or more beaconsand the one or more beaconsduring the probe/scan of the system.

201 206 207 203 204 201 206 207 204 203 201 206 208 203 201 206 208 206 208 203 204 203 201 206 203 204 201 204 200 203 The access pointcan determine that the multiple RSSI measurements associated with the beaconsandwhich comprise identifier information associated with the access point(e.g., MAC address 00:00:03) that has been copied by the rogue access point(e.g., MAC address 00:00:03) and received during the time window, are values, are of a certain value. The access pointcan determine that the multiple RSSI measurements associated with the beaconsandare values such as 30 dB (e.g., received from rogue access point) and 70 dB (e.g., received from access point). The access pointcan determine that collectively, the multiple RSSI measurements from the beaconsandexceed a threshold variance from 70 dB (e.g., the baseline RSSI value associated with access point). The access point, based on the beaconsandcomprising similar identifier information (e.g., MAC address 00:00:03), may be unaware that the beaconsandare from two different devices (e.g., access pointand rogue access point) rather than a single device (e.g., access point). However, the access pointcan determine, based on the collective RSSI measurements received/determined from the beaconsandthat the identifier information (e.g., MAC address 00:00:03) is compromised. The identifier information (e.g., MAC address 00:00:03) can be compromised if it is copied by a device such as the rogue access point, for example. As such, the access pointcan determine that the rogue access pointis present in the systemand that access pointis now a compromised access point (e.g., an access point associated with identifier information that has been copied by a rogue access point)

3 FIG. 300 301 302 116 116 201 203 303 105 200 303 105 301 302 304 102 303 301 123 304 310 301 304 303 301 a b, shows an example system in which the present methods and systems can operate. A systemcan comprise access pointand access point(e.g., authorized access points, network devicesandaccess points-, etc.). The access points can be in communication with a network(e.g., network, system, etc.). The networkcan The networkcan comprise one or more networks, such as a wide area network (e.g., a content network, service network, provider network, the Internet), a public network, an open network, a provider managed network, a non-user managed network, a provider controlled network, a non-user controlled network, a local network, a private network, a closed network, a user managed network, a user controlled network, a user deployed network, and/or the like. Other forms of communications can be used, such as wired and wireless telecommunication channels, for example. The access pointand the access pointcan enable a device, such as the user device(e.g., user device) to be in communication with the network. For example, the access pointcan be configured with connection/identifier information (e.g., SSID, and MAC address 00:00:03) to enable the user deviceto be in communicationwith the access point. The user devicecan be in communication with the networkvia the access point.

303 303 301 302 303 302 301 303 303 303 301 302 301 308 123 302 308 301 302 308 303 An access point in communication with the networkcan determine the presence of another access point in communication with the network. For example, access pointcan determine the presence of access pointin the networkand access pointcan determine the presence of access pointin the network. Any of the steps, methods, actions, and the like performed by an access point in communication with the networkcan be performed by another access point in communication with the network. For example, any steps, methods, actions, and the like performed by access pointcan be performed byand vice versa. The access pointcan periodically and/or consistently transmit/broadcast a beaconcomprising identifier information such as a MAC address (e.g., MAC address 00:00:03), SSID information (e.g., SSID), combinations thereof, and the like, for example. The access pointcan receive the beaconfrom the access point. The access pointcan received the beaconduring periodic probes and/or scans of the network.

308 302 308 302 303 301 308 302 303 302 303 302 302 308 302 302 302 302 The beaconcan comprise and/or be associated with a received signal strength indicator (RSSI). The access pointcan measure/determine a value of the RSSI associated with the beacon. The access pointcan perform a periodic probe/scan of the networkto determine/detect the presence of the access pointbased in a RSSI value determined from the beacon. The access pointcan periodically probe/scan the networkfor a time window. For example, the access pointcan periodically probe/scan the networkfor a time window of 20 microseconds. The access pointcan determine/take multiple RSSI measurements during the time window. For, example, the access pointcan measure a RSSI associated with beaconat regular intervals (e.g., 5 microsecond intervals), such as at 5 microseconds, 10 microseconds, 15 microseconds, and 20 microseconds. The number of multiple RSSI measurements taken/determined by the access pointcan be manually provisioned. For example, the access pointcan be manually configured to take 5, 10, 20, or any number of RSSI measurements during the time window. The number of multiple RSSI measurements taken/determined can be dynamically determined by the access point. For example, the access pointcan automatically determine any number of RSSI measurements to take/determine during the time window.

302 302 301 302 301 302 301 306 104 306 301 302 306 130 303 The access pointcan sum and/or average multiple RSSI values and determine a baseline RSSI value. For example, the access pointcan sum and/or average the multiple RSSI values determined at the regular intervals during the time window and determine that a baseline RSSI value associated with access pointis 70 (e.g., 70 dB). The access pointcan store the identifier information (e.g., MAC address, SSID) associated with access pointwith the determined baseline RSSI value. The access pointcan transmit the identifier information (e.g., MAC address, SSID) associated with access pointwith the determined baseline RSSI value to the computing device(e.g., computing device, server, cloud-based device, etc.). The computing devicecan receive identifier information and baseline RSSI values from a plurality of access points (e.g., access point, access point). The computing devicecan store the identifier information and baseline RSSI values received from the access points as a master list (e.g., master list) comprising identifier information and baseline RSSI values associated with a plurality of devices in communication with the network.

302 123 301 119 305 305 117 204 301 305 301 304 311 303 305 304 311 303 305 310 303 301 The access pointcan determine that the identifier information (e.g., MAC address 00:00:03, SSID) associated with the access pointis compromised. The identifier information can be compromised if the identifier information has been copied (e.g., copied identifier information) by a rogue hotspot. The rogue hotspotcan be a device (e.g., rogue device, rogue access point, unauthorized access point, laptop, etc.) set up by malicious entity that copies and/or assigns similar identifier information as the access point. The rogue hotspotcan to trick, based on the copied identifier information associated with access point, the user deviceinto being in communicationwith the networkvia the rogue hotspot. The user devicecan be unaware that it is in communicationwith the networkvia the rogue hotspotinstead of in communicationwith the networkvia the access point.

305 304 304 304 305 302 123 301 301 The rogue hotspotcan obtain sensitive information associated with the user deviceand/or harm the user device, such as harm caused by malware installed on the user deviceby the rogue hotspot, for example. The access pointcan determine that the identifier information (e.g., MAC address 00:00:03, SSID) associated with the access pointis compromised based on a threshold number of the determined/monitored signal strengths (e.g., RSSI received during a periodic probe/scan) exceeding a variance threshold associated with the baseline signal strength associated with the access point.

302 305 123 301 303 303 302 301 302 301 123 302 301 301 301 301 114 301 301 301 The access pointcan detect the rogue hotspot(e.g., determine that the identifier information (e.g., MAC address 00:00:03, SSID) associated with the access pointis compromised) during a periodic probe/scan of the network. During a periodic probe/scan of the networkthe access pointcan measure multiple RSSIs associated with the access pointduring a time window. The access pointcan determine that the multiple RSSIs are associated with the access pointbased identifier information (e.g., MAC address 00:00:03, SSID). The access point, based on the identifier information, can access the stored information comprising the identifier information associated with the access point, and determine that the multiple RSSIs associated with the access point, determined during the time window, exceed a threshold variance from the baseline signal strength associated with the access point. For example, the access pointcan access a database (e.g., database) comprising the identifier information associated with the access pointand determine that the baseline signal strength associated with the access pointis 70 dB. The RSSI measurements associated with the access point, determined during the time window, can vary in value, such as from 30 dB to 70 dB.

302 308 301 309 305 305 123 301 309 305 303 302 308 309 301 305 302 308 309 301 123 301 123 305 The signal strength (e.g., RSSI) measurements associated with the network device determined during the time window can be vary in value, such as from 30 dB to 70 dB, because the access pointcan receive and measure signal strength (e.g., RSSI) from a beaconthat is broadcast/transmitted by the access pointand a beaconthat is broadcast/transmitted by the rogue hotspot. For example, the rogue hotspotcan copy the identifier information (e.g., MAC address 00:00:03, SSID, etc.) associated with the access pointand periodically and/or consistently transmit/broadcast the beaconcomprising the copied identifier information. The beacon transmitted/broadcast by the rogue hotspotcan be associated with a RSSI value of 30 dB. During a periodic probe/scan of the network, the access pointcan receive the beaconand the beaconfrom the access pointand rogue hotspot, respectively. The access pointmay inaccurately determine that the beaconand the beaconoriginate from a single device (e.g., the access point) based on the identifier information (e.g., MAC address 00:00:03, SSID) broadcast by access pointand the copied identifier information (e.g., MAC address 00:00:03, SSID) broadcast by the rogue hotspotmatching and/or being similar.

305 302 302 309 305 301 The rogue hotspotcan be associated with a signal strength (e.g., RSSI) that is inconsistent in value, fluctuates, and/or exhibits erratic behavior during a time window associated with a periodic scan performed by the access point. From the perspective of the access point, the beaconwill vary in value (e.g., flap) from 70 dB to 30 dB as the access point receives beacons from the rogue deviceand the access point.

302 301 302 302 306 306 130 The changes in signal strength (e.g. RSSI value) within the time widow can exceed a threshold variance from 70 dB. A threshold variance value can be set at any suitable value, for example, +/−1 dB, 2 dB, 3 dB, 4 dB, 5 dB, 6 dB, 7 dB, 8 dB, 9 dB, 10 dB, 11 dB, 12 dB, 13 dB, 14 dB, 15 dB, 16 dB, 17 dB, 18 dB, 19 dB, 20 dB, 21 dB, 22 dB, 23 dB, 24 dB, 25 dB, and the like. One of skill in the art will appreciate that other threshold variances can be used and can vary depending on what measurement is used. The access pointcan determine that the identifier information associated with the access pointis compromised based on a number of the determined/monitored signal strengths exceeding the variance threshold associated with the baseline signal strength of 70 dB. The access pointcan store the identifier information as compromised identifier information. The access pointcan transmit the compromised identifier information to the computing device. The computing devicecan store the compromised identifier information in the master list (e.g., master list). The master list can comprise identifier information associated with a plurality of access points and/or compromised identifier information associated with a plurality of access points.

306 301 306 301 301 304 304 310 303 301 123 306 301 301 304 456 304 312 303 301 456 Based on receiving the compromised identifier information, the computing devicecan transmit a message to the access point. The computing devicecan transmit information (e.g., a message, code, deauthentication frame, etc.) to the access pointthat causes the access pointto deauthenticate/disassociate the user device. As such, the user devicewill be unable to be in communicationwith the networkvia the access pointbased on the compromised identifier information (e.g., MAC address 00:00:03, SSID). The computing devicecan transmit information (e.g., a message, code, etc.) to the access pointthat causes the access pointto authenticate/associate the user devicebased on new identifier information (e.g., MAC address 00:00:04, SSID). As such, the user devicewill be able to be in communicationwith the networkvia the access pointbased on the new identifier information (e.g., MAC address 00:00:04, SSID).

4 FIG. 117 204 116 116 201 203 301 302 a b, is a flowchart of an example method. The method can detect rogue hotspots (e.g., rogue device, rogue access point, unauthorized access points, etc.). For example an authorized (e.g., legitimate, trusted, etc.) access point (e.g., network devicesandaccess points-, access points-) can detect rogue hotspots.

116 116 201 203 301 302 104 116 116 201 203 301 302 118 119 105 200 303 116 116 201 203 301 302 a b, a b, a b, At 402, a device (e.g., network devicesandaccess points-, access points-, computing device, etc.) can determine a baseline signal strength associated with a network device (e.g., authorized access point, network devicesandaccess points-, access points-). The network device can periodically transmit and/or broadcast a beacon comprising identifier information (e.g., a MAC address, SSID, an identifier, identifier information, and identifier information) and/or a signal strength value associated with the network device. The device can determine a baseline signal strength value associated with the network device based on/by measuring signal strengths (e.g., RSSIs) associated with the network device. For example, during an probe/scan of a network (e.g., network, system, network) to determine other devices (e.g., network devices) in the network, an initial list of network devices (e.g., authorized access points, network devicesandaccess points-, access points-, etc.) in communication with the network can be is generated by the device. The device can receive the beacon and multiple signal strength measurements (e.g., RSSIs) associated with the network device can be determined and/or measured. An average and/or summation of determined/measured signal strengths (RSSI) can be stored as a baseline signal strength associated with the network device. For example, multiple received signal strength indications (RSSIs) with a value of 60 (e.g., 60 dB) associated with the network device can be measured and/or received by the device and stored as baseline signal strength (e.g., 60 dB) associated with the network device.

104 306 116 116 201 203 301 302 130 116 116 201 203 301 302 130 a b, a b, The initial list can be stored by the device or by another device. For example, the device can transmit the initial list (or any other generated list such as a list generated by subsequent probes/scans of the network) to a server and/or computing device (e.g., the computing device, computing device, cloud-based device, etc.). The server and/or computing device can receive initial lists (or any other lists) from a plurality of devices (e.g., network devicesandaccess points-, access points-) and generate/store a master list (e.g., master list) comprising the received initial lists. The initial lists can be updated with new RSSI measurements associated with network devices (e.g., authorized access points, network devicesandaccess points-, access points-, etc.) based on subsequent probes/scans by the device. The initial list and/or the master list (e.g., master list) can comprise the identifier information associated with the network device, identifier information associated with other network devices, and RSSI information determined from the network device and/or other network devices.

404 20 At, the device can determine/monitor a signal strength associated with the network identifier information. The device can periodically probe/scan the network for a time window. The device can periodically probe/scan the network for a time window and measure/determine a signal strength associated with the network identifier based beacons transmitted and/or broadcasted by the network device comprising the identifier information and/or a signal strength value (e.g., RSSI) associated with the network device. For example, the device can probe/scan the network for a time window ofmicroseconds and received one or more beacons from the network device during the time window. The one or more beacons can comprise an RSSI value (e.g., decibel value, amplitude value, power value, etc.) associated with the network device. The device can associate the RSSI values with the network device based on identifier information within each beacon received. Additionally, the one or more beacons can inform the device that a signal strength associated with the network device was and/or is provisioned at a certain value (e.g., decibel value, amplitude value, power value, etc.). Further, the provisioned value of the signal strength associated with the network device can be a baseline (e.g., consistent, regular, routine, etc.) signal strength associated with the network device.

406 117 204 130 130 At, the device can determine that the identifier information associated with the network device is compromised. The identifier information associated with the network device can be compromised if the identifier information associated with the network device has been copied by a rogue hotspot (e.g., rogue device, rogue access point, unauthorized access points, etc.). The device can determine that the identifier information associated with the network device is compromised based on a threshold quantity/number of the determined/monitored signal strengths (e.g., RSSI received during a periodic probe/scan) exceeding a variance threshold associated with the baseline signal strength associated with the network device. During a periodic probe/scan of the network the device can measure multiple RSSIs associated with the network device during a time window. The device can determine that the multiple RSSIs are associated with the network device based on associated identifier information. The device, based on the identifier information, can access the initial list and/or the master list (e.g., master list) comprising the identifier information associated with the network device, and determine that the multiple RSSIs associated with the network device determined during the time window exceed a threshold variance from the baseline signal strength associated with the network device. For example, the device can access the initial list and/or the master list (e.g., master list) comprising the identifier information associated with the network device and determine that the baseline signal strength associated with the network device is 70 dB. The multiple RSSIs associated with the network device determined during the time window can be values such as 69 dB, 30 dB, 68 dB, 31 dB etc.

117 204 117 204 118 119 The RSSIs associated with the network device determined during the time window can be values such as 69 dB, 30 dB, 68 dB, 31 dB etc. because a rogue hotspot (e.g., rogue device, rogue access point, unauthorized access points, etc.) may be present in the network. The rogue hotspot (e.g., rogue device, rogue access point, unauthorized access points, etc.) can be a device set up by a malicious entity that copies and/or assigns similar identifier information (e.g., identifier information, identifier information, MAC address, SSID) as the network device. For example, the rogue hotspot can copy the identifier information associated with the network device and periodically and/or consistently transmit/broadcast one or more beacons comprising the copied identifier information. The one or more beacons transmitted/broadcast by the rogue hotspot can be associated with a RSSI value (e.g., 30 dB). During a periodic probe/scan of the network, the device can received beacons from the network device and the rogue hotspot. The device may perceive/determine the beacons as originating from a single device (e.g., the network device) based on the identifier information and copied identifier information matching and/or being similar. The rogue hotspot can be associated with an RSSI that is inconsistent in value, fluctuates, and/or exhibits erratic behavior during a time window associated with a periodic scan performed by the device. For example, the rogue hotspot can be associated with an RSSI values that range from 70 dB to 30 dB within the time widow associated with the periodic probe/scan. The device can determine RSSI values during the time window to be values such as 69 dB, 30 dB, 68 dB, 31 dB, and the like, because the network device and the rogue hotspot are both transmitting/broadcasting RSSIs associated with the identifier information that are received by the device.

The changes in value (e.g., 69 dB, 30 dB, 68 dB, 31dB) within the time widow can exceed a threshold variance from 70 dB. A threshold variance value can be set at any suitable value, for example, +/−1 dB, 2 dB, 3 dB, 4 dB, 5 dB, 6 dB, 7 dB, 8 dB, 9 dB, 10 dB, 11 dB, 12 dB, 13 dB, 14 dB, 15 dB, 16 dB, 17 dB, 18 dB, 19 dB, 20 dB, 21 dB, 22 dB, 23 dB, 24 dB, 25 dB, and the like. One of skill in the art will appreciate that other threshold variances can be used and can vary depending on what measurement is used. The device can determine that the identifier information associated with the network device is compromised based on a quantity/number of the determined/monitored signal strengths (RSSIs) exceeding the variance threshold associated with the baseline signal strength of 70 dB. The device can store the identifier information associated with the network device as a compromised identifier and/or compromised identifier information.

408 104 306 130 At, the device can transmit an indication of the compromised identifier. For example, the device can transmit the compromised identifier information to the server and/or computing device (e.g., computing device, computing device, cloud-based device, etc.). The server and/or computing device can store the compromised identifier information in the master list (e.g., master list). The master list can comprise identifier information associated with a plurality of network devices and/or compromised identifier information associated with a plurality of network devices.

5 FIG. 502 104 306 116 116 201 203 301 302 105 303 118 119 116 116 201 203 301 302 a b, a b, is a flowchart of an example method. At, a computing device (e.g., computing device, computing device, server, cloud-based device, etc.) can receive information associated with signal strength from a plurality of network devices (e.g., authorized access points, network devicesandaccess points-, access points-, etc.) in a network (e.g., network, network). Each of the plurality of network devices can determine a signal strength associated with other network devices in the network by measuring a signal strength (RSSI) and/or determining a signal strength value (e.g., decibel value, amplitude value, power value, integrity value, etc.) associated with beacon(s) received from the other network devices. For example, a network device of the plurality of network devices can receive, during a periodic probe/scan of the network, one or more beacons from other network devices. The beacons can comprise identifier information (e.g., identifier information, identifier information, MAC address, SSID, etc.) associated with the other network devices. The network device can determine that the beacons are associated with each of the other network devices based on the identifier information. The beacons can comprise signal strength indicators (e.g., RSSIs). The network device can determine signal strengths associated with each of the other network devices by measuring a value to the RSSIs. The network device can determine a baseline signal strength associated with each of the other network devices by measuring the value to the RSSIs received. For example, during an initial probe/scan of the network to determine other network devices in the network (e.g., network device discovery, access point discovery, etc.) an initial list of the other network devices (e.g., authorized access points, network devicesandaccess points-, access points-, etc.) in communication with the network can be is generated (e.g., obtained by probe/scan) by the network device. A RSSI value (e.g., 60 dB) for each of the other network devices can be measured and stored as a baseline signal strength associated with each of the other network devices. The network device can store the initial list or another device such as the computing device can store the initial list. For example, the network device can transmit the initial list (or any other list) to the computing device. The computing device can receive initial lists (e.g., information associated with signal strength) from each of the plurality of network devices.

504 130 At, the computing device can generate a master list comprising identifier information and information associated with signal strength associated with each of the plurality of network devices. For example, the computing device can receive the initial lists from each of the plurality of network devices and store the initial lists as a master list (e.g., mater list). The master list can be updated with new RSSI measurements associated each of the plurality of network devices based on subsequent probes/scans of the network performed by each of the plurality of network devices.

506 117 204 At, the computing device can receive information associated with a compromised identifier. The compromised identifier can be associated with a network device of the plurality of network devices. The information associated with the compromised identifier can be received from one or more network devices of the plurality of network devices. For example, a network device can determine that identifier information associated with another network device is compromised. The identifier information can be compromised if the identifier information has been copied by a rogue hotspot (e.g., rogue device, rogue access point, unauthorized access points, etc.). The network device of the plurality of network devices can determine that identifier information associated with another network device is compromised based on a threshold quantity/number of the determined/monitored signal strengths exceeding a variance threshold associated with the baseline signal strength associated with the other network device. For example, during a periodic probe/scan of the network the network device can measure multiple RSSIs associated with other network devices during a time window. The network device can determine that the multiple RSSIs are associated with the other devices based on associated identifier information. The network device, based on the identifier information, can access stored information such as list of network devices that comprises baseline signal strength information associated with each of the plurality of network devices. The network device can access the initial list determine that the baseline signal strength associated another device is 70 dB. The network device can determine that measured multiple RSSIs associated with another network device are values such as 69 dB, 30 dB, 68 dB, 31 dB etc.

117 204 118 119 The measured multiple RSSIs associated with another network device can be values such as 69 dB, 30 dB, 68 dB, 31 dB etc. because a rogue hotspot may be present in the network. The rogue hotspot (e.g., rogue device, rogue access point, unauthorized access points, etc.) can be a device such as a smartphone, laptop, tablet, computer, mobile computing device, and the like, set up by malicious entity to copy and/or assign similar identifier information (e.g., identifier information, identifier information, MAC address, SSID) as another network device. For example, the rogue hotspot can copy the identifier information associated with another network device and periodically and/or consistently transmit/broadcast one or more beacons comprising the copied identifier information. The one or more beacons transmitted/broadcast by the rogue hotspot can be associated with a RSSI value (e.g., 30 dB).

118 During a periodic probe/scan of the network, the network device of the plurality of network devices can receive beacons from both another network device and the rogue hotspot. The network device may perceive/determine the beacons as originating from a single device (e.g., another network device) based on the identifier information (e.g., identifier information associated with another device) and the copied identifier information (e.g., identifier information copied by the rogue hotspot) matching and/or being similar. The rogue hotspot can be associated with an RSSI that is inconsistent in value, fluctuates, and/or exhibits erratic behavior during a time window associated with a periodic scan performed by the network device. For example, the rogue hotspot can be associated with an RSSI values that range from 70 dB to 30 dB within the time widow associated with the periodic probe/scan. As such, the network device can determine RSSI values during the time window to be values such as 69 dB, 30 dB, 68 dB, 31 dB etc. The changes in value (e.g., 69 dB, 30 dB, 68 dB, 31dB) within the time widow can exceed a threshold variance from 70 dB. A threshold variance value can be set at any suitable value, for example, +/−1 dB, 2 dB, 3 dB, 4 dB, 5 dB, 6 dB, 7 dB, 8 dB, 9 dB, 10 dB, 11 dB, 12 dB, 13 dB, 14 dB, 15 dB, 16 dB, 17 dB, 18 dB, 19 dB, 20 dB, 21 dB, 22 dB, 23 dB, 24 dB, 25 dB, and the like. One of skill in the art will appreciate that other threshold variances can be used and can vary depending on what measurement is used. The network device can determine, based on the RSSI associated with the rogue device not coinciding/reconciling with the baseline RSSI associated with another network device (e.g., the RSSI measurements exceeding the threshold variance), that the other network device is compromised. The network device is compromised if identifier information associated with network device has been copied (e.g., identifier information) by a rogue hotspot. The network device can transmit information associated with a compromised identifier to the computing device. The computing device can receive the information associated with a compromised identifier.

508 130 At, the computing device can use the information associated with the compromised identifier to update the master list (e.g., master list). As such, the master list can comprise identifier information for each of the plurality of network devices in the network and compromised identifier information for each of the plurality of network devices in the network that are associated with identifier information that has been copied by a rogue hotspot.

510 102 304 At, the computing device can transmit a message (e.g., information) to the network device associated with the identifier information that has been compromised (e.g., copied by a rogue hotspot). The computing device can transmit a message/information (e.g., a code, deauthentication frame, etc.) to the network device that causes the network device to deauthenticate/disassociate devices (e.g., user device, user device, mobile devices, network devices, etc.) in communication and/or associated with the network device based on the copied identifier information (e.g., identifier information copied by a rogue hotspot).

The computing device can transmit a message/information (e.g., a code, etc.) to the network device (e.g., the network device associated with the identifier information that was copied by the rogue hotspot) that that causes the network device to change/modify its associated identifier information. For example, a message can be sent to the network device that causes the network device to change a SSID and/or MAC address to which it is associated with to a new SSID and/or MAC address. The rogue hotspot will be unaware of the new identifier information. For example, the rogue hotspot will be unaware of the new SSID and/or MAC address associated with the network device. Devices that were previously connected to/in communication with the network device can reconnect, re-associate with, and/or be in communication with the network device based on the new identifier information.

6 FIG. 602 116 116 201 203 301 302 116 116 201 203 301 302 104 116 116 201 203 301 302 105 118 119 a b, a b, a b, is a flowchart of an example method. At, an expected signal strength can be received. The expected signal strength can be received from a first network device (e.g., network devicesandaccess points-, access points-, authorized access point, etc.). The expected signal strength can be received by a device (e.g., network devicesandaccess points-, access points-, authorized access point, computing device, remote computing device, etc.). The expected signal strength can be associated with a second network device (e.g., network devicesandaccess points-, access points-, authorized access point, etc.). The expected signal strength can be a manually provisioned signal strength. For example, the first network device may be manually provisioned during an initial network deployment, network discovery/set-up, network arrangement, and the like. The expected signal strength can be a dynamically determined signal strength. The expected signal strength can be determined by the first network device during a probe/scan of a network (e.g., network) where the first network device measures a signal strength (e.g., received signal strength, RSSI, etc.) associated with the second network device for a duration/time window. For example, the first network device can probe/scan the network for a time window of 20 microseconds and receive one or more beacons from the second network device during the time window. The one or more beacons can comprise an RSSI value (e.g., decibel value, amplitude value, power value, etc.) associated with the second network device. The first device can associate the RSSI values with the second network device based on identifier information (e.g., identifier information, identifier information) associated with each beacon received. The identifier information can be associated with the second network device and include a service set identifier (SSID), a media access control (MAC) address, combinations thereof, and the like. The first network device can store and/or transmit the expected signal strength (and the identifier information).

604 105 At, a measured signal strength can be received. The measured signal strength can be received from the first network device. The measured signal strength can be associated with the second network device. The measured signal strength can be determined by the first network device during a probe/scan of the network (e.g., network). During the probe/scan of the network, the first network device can measure a signal strength (e.g., received signal strength, RSSI, etc.) associated with the second network device for a duration/time window. For example, the first network device can probe/scan the network for a time window of 20 microseconds and receive one or more beacons from the second network device during the time window. The one or more beacons can comprise an RSSI value (e.g., decibel value, amplitude value, power value, etc.) associated with the second network device that is measured by the first network device. Based on measuring, such as during a probe/scan of the network, signal strengths associated with the second network device, the first network device can store and/or transmit the measured signal strength.

606 116 116 201 203 301 302 104 117 204 a b, At, it can be determined that the second network device is compromised. For example, the device (e.g., network devicesandaccess points-, access points-, authorized access point, computing device, remote computing device, etc.) can determine that the second network device is compromised. The device can determine that the second network device is compromised (e.g., the identifier information associated with the second network device is compromised) based on a variance between the expected signal strength and the measured signal strength exceeding a threshold. For example, the expected signal strength can be at a value of 70 dB and the measured signal strength can be a value of 30 dB. The measured signal strength can be at the value of 30 dB because a rogue hotspot (e.g., rogue device, rogue access point, unauthorized access points, etc.) may be present in the network.

118 119 The rogue hotspot can be a device set up by a malicious entity that copies and/or assigns similar identifier information (e.g., identifier information, identifier information, MAC address, SSID) as the second network device. For example, the rogue hotspot can copy the identifier information associated with the second network device and periodically and/or consistently transmit/broadcast one or more beacons comprising the copied identifier information. The one or more beacons transmitted/broadcast by the rogue hotspot can be associated with a RSSI value of 30 dB. During a probe/scan of the network, the first device can receive beacons from the second network device and the rogue hotspot. The first network device may mistakenly determine the beacons as originating from a single device (e.g., the second network device) based on the identifier information and copied identifier information matching and/or being similar. The rogue hotspot can be associated with an RSSI that is inconsistent in value, fluctuates, and/or exhibits erratic behavior during a time window associated with a probe/scan of the network by the first network device. The difference in value between the expected signal strength and the measured signal strength can exceed a threshold variance from 70 dB. A threshold variance value can be set at any suitable value, for example, +/−1 dB, 2 dB, 3 dB, 4 dB, 5 dB, 6 dB, 7 dB, 8 dB, 9 dB, 10 dB, 11 dB, 12 dB, 13 dB, 14 dB, 15 dB, 16 dB, 17 dB, 18 dB, 19 dB, 20 dB, 21 dB, 22 dB, 23 dB, 24 dB, 25 dB, and the like. One of skill in the art will appreciate that other threshold variances can be used and can vary depending on what measurement is used. As such, the device can determine that the identifier information associated with the second network device is compromised based on the variance between the expected signal strength and the measured signal strength exceeding the threshold. The device can store the identifier information associated with the second network device as compromised identifier information.

608 102 At, a message can be transmitted to the second network device. For example, the device can transmit the message to the second network device. The message can be transmitted in response to the variance between the expected signal strength and the measured signal strength exceeding the threshold. The message can causes the second network device to disconnect any user devices in communication with the second network device based on the identifier information associated with the second network device. For example, the message can be a deauthentication message (e.g., deauthentication frame, disassociate frame, etc.). The message can cause the second network device to change its associated identifier information to new network identifier information. The message can also causes the second network device be in communication, via the new identifier information, with at least one device (e.g., user device, user device, etc.) that was in communication with the second network device based on the compromised identifier information.

7 FIG. 702 116 116 201 203 301 302 105 116 116 201 203 301 302 118 119 a b, a b, is a flowchart of an example method. At, a baseline signal strength can be determined. The baseline signal strength can be determined by a device (e.g., network devicesandaccess points-, access points-, authorized access point, etc.) in a network (e.g., network). The baseline signal strength can be associated with a network device (e.g., network devicesandaccess points-, access points-, authorized access point, etc.). The baseline signal strength can be a manually provisioned signal strength. For example, the device can be manually provisioned during an initial network deployment, network discovery/set-up, network arrangement, and the like. The baseline signal strength can be a dynamically determined signal strength. The baseline signal strength can be determined by the device during a probe/scan of the network. During the probe/scan of the network the device can measure a signal strength (e.g., received signal strength, RSSI, etc.) associated with the network device for a duration/time window. For example, the device can probe/scan the network for a time window of 20 microseconds and receive one or more beacons from the network device during the time window. The device can summate (e.g., average) the RSSI values to determine the baseline signal strength. The one or more beacons can comprise an RSSI value (e.g., decibel value, amplitude value, power value, etc.) associated with the network device. The device can associate the RSSI values with the network device based on identifier information (e.g., identifier information, identifier information) associated with each beacon received. The identifier information can be associated with the network device and include a service set identifier (SSID), a media access control (MAC) address, combinations thereof, and the like. The device can store and/or transmit the baseline signal strength (and the identifier information).

702 At, the device can determine that for a quantity/number of times within a time window, a signal strength associated with the network device exceeds a threshold variance from the baseline signal strength. The device can determine that the signal strength associated with the network device exceeds the threshold variance from the baseline signal strength based on a probe/scan of the network. For example, the baseline signal strength can be 70 dB. The device, during a probe/scan of the network, can receive beacons from the network device and a rogue hotspot. The device may mistakenly determine that the beacons originate from a single device (e.g., the network device) based on the identifier information. For example, the rogue hotspot can copy the identifier information associated with the network device and broadcast beacons associated with the copied identifier information. The rogue hotspot can be associated with signal strengths that are inconsistent in value, fluctuate, and/or exhibits erratic behavior during a time window associated with a probe/scan of the network by the device. The difference in value between the baseline signal strength and the signal strength associated with the network device can exceed a threshold variance from 70 dB. A threshold variance value can be set at any suitable value, for example, +/−1 dB, 2 dB, 3 dB, 4 dB, 5 dB, 6 dB, 7 dB, 8 dB, 9 dB, 10 dB, 11 dB, 12 dB, 13 dB, 14 dB, 15 dB, 16 dB, 17 dB, 18 dB, 19 dB, 20 dB, 21 dB, 22 dB, 23 dB, 24 dB, 25 dB, and the like. One of skill in the art will appreciate that other threshold variances can be used and can vary depending on what measurement is used. As such, the device can determine that the identifier information associated with the network device is compromised based on the variance between the baseline signal strength and the signal strength associated with the network device exceeding the threshold. The device can store the identifier information associated with the network device as compromised identifier information.

704 102 At, the device can transmit a message to the network device. The device can transmit the message to the network device in response to the signal strength exceeding the threshold. The message can be transmitted in response to the variance between the baseline signal strength and the signal strength exceeding the threshold. The message can causes the network device to disassociate from any user devices in communication with the network device based on the identifier information associated with the network device. For example, the message can be a deauthentication message (e.g., deauthentication frame, disassociate frame, etc.). The message can cause the network device to change its associated identifier information to new identifier information. The message can also causes the network device be in communication, via the new identifier information, with at least one device (e.g., user device, user device, etc.) that was in communication with the network device based on the compromised identifier information.

801 102 104 116 117 201 203 204 301 302 304 305 306 8 FIG. 8 FIG. 8 FIG. The methods and systems can be implemented on a computer(e.g., computing device) as shown inand described below. By way of example, the user device, the computing device, the network device, the rogue device, the access points-, the rogue access point, the access points-, the user device, the rogue device, and the cloud-based devicecan be a computer as shown in. Similarly, the methods and systems disclosed can utilize one or more computers to perform one or more functions in one or more locations.is a block diagram of an example operating environment for performing the disclosed methods. This example operating environment is only an example of an operating environment and is not intended to suggest any limitation as to the scope of use or functionality of operating environment architecture. Neither should the operating environment be interpreted as having any dependency or requirement relating to any one or combination of components shown in the example operating environment.

The present methods and systems can be operational with numerous other general purpose or special purpose computing system environments or configurations. Examples of well-known computing systems, environments, and/or configurations that can be suitable for use with the systems and methods comprise, but are not limited to, personal computers, server computers, laptop devices, and multiprocessor systems. Additional examples comprise set top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, distributed computing environments that comprise any of the above systems or devices, and the like.

The processing of the disclosed methods and systems can be performed by software components. The disclosed systems and methods can be described in the general context of computer-executable instructions, such as program modules, being executed by one or more computers or other devices. Generally, program modules comprise computer code, routines, programs, objects, components, data structures, etc. that perform particular tasks or implement particular abstract data types. The disclosed methods can also be practiced in grid-based and distributed computing environments where tasks are performed by remote processing devices that are linked through a communications network. In a distributed computing environment, program modules can be located in both local and remote computer storage media including memory storage devices.

801 801 803 812 813 803 812 Further, one skilled in the art will appreciate that the systems and methods disclosed herein can be implemented via a general-purpose computing device in the form of a computer. The components of the computercan comprise, but are not limited to, one or more processors, a system memory, and a system busthat couples various system components including the one or more processorsto the system memory. The system can utilize parallel computing.

813 813 803 804 805 806 807 808 812 810 809 811 802 814 814 814 a b c The system busrepresents one or more of several possible types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, or local bus using any of a variety of bus architectures. By way of example, such architectures can comprise an Industry Standard Architecture (ISA) bus, a Micro Channel Architecture (MCA) bus, an Enhanced ISA (EISA) bus, a Video Electronics Standards Association (VESA) local bus, an Accelerated Graphics Port (AGP) bus, and a Peripheral Component Interconnects (PCI), a PCI-Express bus, a Personal Computer Memory Card Industry Association (PCMCIA), Universal Serial Bus (USB) and the like. The bus, and all buses specified in this description can also be implemented over a wired or wireless network connection and each of the subsystems, including the one or more processors, a mass storage device, an operating system, rogue device detection software, signal and identifier data, a network adapter, the system memory, an Input/Output Interface, a display adapter, a display device, and a human machine interface, can be contained within one or more remote computing devices,,at physically separate locations, connected through buses of this form, in effect implementing a fully distributed system.

801 801 812 812 807 805 806 803 The computertypically comprises a variety of computer readable media. Example readable media can be any available media that is accessible by the computerand comprises, for example and not meant to be limiting, both volatile and non-volatile media, removable and non-removable media. The system memorycomprises computer readable media in the form of volatile memory, such as random access memory (RAM), and/or non-volatile memory, such as read only memory (ROM). The system memorytypically contains data such as the signal and identifier dataand/or program modules such as the operating systemand the rogue device detection softwarethat are immediately accessible to and/or are presently operated on by the one or more processors.

801 804 801 804 8 FIG. The computercan also comprise other removable/non-removable, volatile/non-volatile computer storage media. By way of example,shows the mass storage devicewhich can provide non-volatile storage of computer code, computer readable instructions, data structures, program modules, and other data for the computer. For example and not meant to be limiting, the mass storage devicecan be a hard disk, a removable magnetic disk, a removable optical disk, magnetic cassettes or other magnetic storage devices, flash memory cards, CD-ROM, digital versatile disks (DVD) or other optical storage, random access memories (RAM), read only memories (ROM), electrically erasable programmable read-only memory (EEPROM), and the like.

804 805 806 805 806 806 807 804 807 Optionally, any quantity/number of program modules can be stored on the mass storage device, including by way of example, the operating systemand the rogue device detection software. Each of the operating systemand the rogue device detection software(or some combination thereof) can comprise elements of the programming and the rogue device detection software. The signal and identifier datacan also be stored on the mass storage device. The signal and identifier datacan be stored in any of one or more databases known in the art. Examples of such databases comprise, DB2®, Microsoft® Access, Microsoft® SQL Server, Oracle®, MySQL, PostgreSQL, and the like. The databases can be centralized or distributed across multiple systems.

801 803 802 813 The user can enter commands and information into the computervia an input device (not shown). Examples of such input devices comprise, but are not limited to, a keyboard, pointing device (e.g., a “mouse”), a microphone, a joystick, a scanner, tactile input devices such as gloves, and other body coverings, and the like These and other input devices can be connected to the one or more processorsvia the human machine interfacethat is coupled to the system bus, but can be connected by other interface and bus structures, such as a parallel port, game port, an IEEE 1394 Port (also known as a Firewire port), a serial port, or a universal serial bus (USB).

811 813 809 801 809 801 811 811 811 801 810 811 801 The display devicecan also be connected to the system busvia an interface, such as the display adapter. It is contemplated that the computercan have more than one display adapterand the computercan have more than one display device. For example, the display devicecan be a monitor, an LCD (Liquid Crystal Display), or a projector. In addition to the display device, other output peripheral devices can comprise components such as speakers (not shown) and a printer (not shown) which can be connected to the computervia the Input/Output Interface. Any step and/or result of the methods can be output in any form to an output device. Such output can be any form of visual representation, including, but not limited to, textual, graphical, animation, audio, tactile, and the like. The display deviceand computercan be part of one device, or separate devices.

801 814 814 814 801 814 814 814 815 808 808 a b c. a b c The computercan operate in a networked environment using logical connections to one or more remote computing devices,,By way of example, a remote computing device can be a personal computer, portable computer, smartphone, a server, a router, a network computer, a peer device or other common network node, and so on. Logical connections between the computerand a remote computing device,,can be made via a network, such as a local area network (LAN) and/or a general wide area network (WAN). Such network connections can be through the network adapter. The network adaptercan be implemented in both wired and wireless environments. Such networking environments are conventional and commonplace in dwellings, offices, enterprise-wide computer networks, intranets, and the Internet.

805 801 803 806 Application programs and other executable program components such as the operating systemare shown herein as discrete blocks, although it is recognized that such programs and components reside at various times in different storage components of the computing device, and are executed by the one or more processorsof the computer. An implementation of the rogue device detection softwarecan be stored on or transmitted across some form of computer readable media. Any of the disclosed methods can be performed by computer readable instructions embodied on computer readable media. Computer readable media can be any available media that can be accessed by a computer. By way of example and not meant to be limiting, computer readable media can comprise “computer storage media” and “communications media.” “Computer storage media” comprise volatile and non-volatile, removable and non-removable media implemented in any methods or technology for storage of information such as computer readable instructions, data structures, program modules, or other data. Example computer storage media comprises, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium which can be used to store the desired information and which can be accessed by a computer.

The methods and systems can employ Artificial Intelligence techniques such as machine learning and iterative learning. Examples of such techniques include, but are not limited to, expert systems, case based reasoning, Bayesian networks, behavior based AI, neural networks, fuzzy systems, evolutionary computation (e.g., genetic algorithms), swarm intelligence (e.g., ant algorithms), and hybrid intelligent systems (e.g., Expert inference rules generated through a neural network or production rules from statistical learning).

While the methods and systems have been described in connection with specific examples, it is not intended that the scope be limited to the particular example set forth, as the examples herein are intended in all respects to be example rather than restrictive.

Unless otherwise expressly stated, it is in no way intended that any method set forth herein be construed as requiring that its steps be performed in a specific order. Accordingly, where a method claim does not actually recite an order to be followed by its steps or it is not otherwise specifically stated in the claims or descriptions that the steps are to be limited to a specific order, it is in no way intended that an order be inferred, in any respect. This holds for any possible non-express basis for interpretation, including: matters of logic with respect to arrangement of steps or operational flow; plain meaning derived from grammatical organization or punctuation; the number or type of examples described in the specification.

It will be apparent to those skilled in the art that various modifications and variations can be made without departing from the scope or spirit. Other examples will be apparent to those skilled in the art from consideration of the specification and practice disclosed herein. It is intended that the specification and examples be considered as examples only, with a true scope and spirit being indicated by the following claims.

Classification Codes (CPC)

Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.

Patent Metadata

Filing Date

March 24, 2026

Publication Date

August 6, 2026

Inventors

Ryan Van Antwerp
James Bradley Hein

Want to explore more patents?

Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.

Citation & reuse

Analysis on this page is generated by Patentable — an AI-powered patent intelligence platform. AI-generated summaries, explanations, and analysis may be reused with attribution and a visible link back to the canonical URL below. Patent abstracts and claims are USPTO public domain.

Cite as: Patentable. “METHODS AND SYSTEMS TO DETECT ROGUE HOTSPOTS” (US-20260230826-A1). https://patentable.app/patents/US-20260230826-A1

© 2026 Patentable. All rights reserved.

Patentable is a research and drafting-assistant tool, not a law firm, and does not provide legal advice. Documents we generate are drafts for review by a licensed patent attorney.

METHODS AND SYSTEMS TO DETECT ROGUE HOTSPOTS — Ryan Van Antwerp | Patentable